如何禁用WordPress的/upgrade.php升级页面以提升安全性?
Hey there! Blocking access to upgrade.php is a smart move to stop your WordPress version from being exposed. Let's go through a few straightforward, reliable ways to get this done:
方法1:使用.htaccess文件(推荐)
This is the most efficient method since it works at the server level, before WordPress even loads.
- Log into your server via FTP, SFTP, or your hosting control panel's file manager.
- Locate the
.htaccessfile in your WordPress root directory (if you don't see it, make sure hidden files are enabled, or create a new file named.htaccess). - Add this code at the end of the file:
<Files "upgrade.php"> Order Allow,Deny Deny from all </Files>
- Save the file. Now any attempt to access
upgrade.phpwill return a 403 Forbidden error, keeping your version info safe.
方法2:通过主题的functions.php文件
If you prefer handling it within WordPress itself, this code-based method works well:
- Head to your WordPress dashboard, go to Appearance > Theme File Editor.
- Find the
functions.phpfile for your active theme in the right-hand sidebar. - Paste this code at the very end of the file:
add_action('init', 'block_upgrade_page_access'); function block_upgrade_page_access() { if (basename($_SERVER['PHP_SELF']) === 'upgrade.php') { wp_die('Access Denied', 'Forbidden', array('response' => 403)); } }
- Save your changes. Anyone trying to load
upgrade.phpwill see a WordPress-native 403 message.
方法3:使用安全插件(无代码选项)
If you're not comfortable editing files, a security plugin can handle this for you:
- Install and activate a reputable WordPress security plugin like Wordfence or iThemes Security.
- Navigate to the plugin's file protection or hardening section.
- Look for an option to block access to sensitive files, then add
upgrade.phpto the blocked list.
Quick Notes:
- Always back up
.htaccessorfunctions.phpbefore making changes—just in case something goes wrong, you can restore the original file. - If you ever need to access
upgrade.phptemporarily (for troubleshooting), just comment out the code you added (add#before each line in.htaccess, or//before the function lines infunctions.php).
内容的提问来源于stack exchange,提问作者Samuel
相关产品推荐
相关产品推荐

